Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised

Discussion in 'News Aggregator' started by The Hacker News, 28 Apr 2025.

  1. Threat actors have been observed exploiting two newly disclosed critical security flaws in Craft CMS in zero-day attacks to breach servers and gain unauthorized access. The attacks, first observed by Orange Cyberdefense SensePost on February 14, 2025, involve chaining the below vulnerabilities - CVE-2024-58136 (CVSS score: 9.0) - An improper protection of alternate path flaw in the Yii PHP

    Continue reading...
     

Share This Page

Loading...